Unified Access Control Framework for Heterogeneous Data Sets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face challenges in managing and sharing data across multiple, disparate data sets in a secure and auditable manner, leading to inefficiencies and inconsistencies in access control management, which hinders data discovery and timely access for consumers.
Innovation Solution
A centralized permissions management framework is implemented to unify access control and auditing across heterogeneously owned data sets, allowing data publishers to define granular permissions and manage access at various levels, while providing a hybrid data catalog for unified metadata management and discovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple separate data stores with distinct access controls are used to manage disparate data sets, then data security and ownership control are maintained, but access control management complexity and administrative burden increase
Solution Approach 1:
The patent combines multiple separate access control systems into a unified access control system that manages permissions across all data stores centrally. The unified system maintains security by implementing consistent access control policies while eliminating the need to manage multiple distinct access control systems, thereby reducing complexity while preserving security.
Solution Approach 2:
The unified access control system serves as a universal management mechanism that handles access control for multiple heterogeneous data stores through a single interface. It provides multi-functional capabilities including centralized permission management, policy enforcement, and auditing across diverse data sources, replacing the need for separate access control mechanisms for each data store.
2Reliability
If multiple separate data stores with distinct access controls are used to manage disparate data sets, then data ownership and access control are maintained, but the number of data consumers that can access data sets decreases
Solution Approach 1:
By merging access control management into a unified system, the patent enables data consumers to access multiple data sets through a single authorization process. This eliminates the need for consumers to navigate multiple separate access control systems, thereby improving access efficiency while maintaining security through centralized policy enforcement.
Solution Approach 2:
The unified access control system provides universal access management that allows data consumers to access heterogeneous data sets through a common interface. This multi-functional approach enables single sign-on and centralized permission management, improving productivity by reducing access barriers while maintaining robust access control.
3Adaptability or versatility
If multiple separate data stores are used to manage disparate data sets, then data set autonomy and ownership are preserved, but data discovery and timely access for consumers are hindered
Solution Approach 1:
The patent introduces a unified access control system as an intermediary layer between data consumers and multiple autonomous data stores. This mediator provides centralized management and discovery capabilities, allowing consumers to find and access data sets efficiently without compromising the autonomy and ownership of individual data stores. The intermediary handles authorization and coordination while data stores maintain their independence.
4Productivity
If a centralized permissions management framework is implemented to unify access control, then access control management efficiency is improved, but system complexity increases
Solution Approach 1:
The unified access control system is implemented as a modular, segmented architecture that manages different aspects of access control independently. This segmentation allows the system to handle complex permissions management tasks through discrete, manageable components, improving efficiency while controlling complexity through organized modularity and clear separation of concerns.
Data Source
AI summary
Features are disclosed for managing multiple heterogeneously owned data stores (e.g., data sets, data lakes) and provisioning a framework for data consumers and data publishers. A computing device can obtain a plurality of data catalogs associated with the data stores. For example, the computing device may update a hybrid data catalog with information from the plurality of data catalogs. The computing device can further provide a portion of the plurality of data catalogs to a data consumer. The computing device may provide the portion of the plurality of data catalogs based on permissions provided by the data publisher. In response, the computing device can receive a request to access a data store associated with the plurality of data catalogs. The computing device can transmit the request to a corresponding data publisher and, based on a response by the data publisher, may modify the distinct access controls for the data store.


